Vulnerabilities exploitable today
353,604in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,655
New KEV · 24H0
Exploit Today ≥ 701,602
Distribution · last window
- Critical2,451
- High8,318
- Medium7,448
- Low696
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-39692—4.3%
——1——CVE-2022-50389—4.3%
——1——CVE-2022-50327—4.3%
——1——CVE-2023-53641—4.3%
——1——CVE-2025-38091—4.3%
——1——CVE-2026-7494—4.3%
——1Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.14dCVE-2023-53477—4.3%
——1——CVE-2023-53182—4.3%
——1——CVE-2022-50321—4.3%
——1——CVE-2023-53314—4.3%
——1——CVE-2023-53223—4.3%
——1——CVE-2022-50313—4.3%
——1——CVE-2022-50427—4.3%
——1——CVE-2021-30309—4.3%
——1——CVE-2022-50286—4.3%
——1——CVE-2025-14972—4.3%
——1——CVE-2025-21013—4.3%
——1——CVE-2025-39693—4.3%
——1——CVE-2023-53268—4.3%
——1——CVE-2022-38688—4.3%
——1——CVE-2025-32881—4.3%
——1——CVE-2023-53604—4.3%
——1——CVE-2023-53737—4.3%
——1——CVE-2026-12454—4.3%
——1——CVE-2025-20691—4.3%
——1——CVE-2025-20690—4.3%
——1——CVE-2025-20689—4.3%
——1——CVE-2026-90613.5 LOW4.3%
——1The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).8dCVE-2022-50380—4.3%
——1——CVE-2023-53498—4.3%
——1——CVE-2022-50537—4.3%
——1——CVE-2026-46022—4.3%
——1——CVE-2023-53224—4.3%
——1——CVE-2026-33694—4.3%
——1——CVE-2023-53451—4.3%
——1——CVE-2026-528393.3 LOW4.3%
——1Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints `appointments/store` and `appointments/update` only check generic appointment privileges and never verify that the submitted `id_users_provider` belongs to the current session. A normal authenticated provider can inject new appointments into another provider's schedule via `store`, or reassign existing appointments into a foreign provider's calendar via `update`. The `store` path contains an additional write-before-crash bug: the unauthorized row is committed to the database before the controller crashes on a type error, so the attacker receives an error response while the foreign appointment is already persisted. Version 1.6.0 patches the issue.14dCVE-2022-50264—4.3%
——1——CVE-2023-53309—4.3%
——1——CVE-2022-50291—4.3%
——1——CVE-2024-20262—4.3%
——1——